CVE-2026-82269

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 20:20

Updated : 2026-08-28 22:16


NVD link : CVE-2026-82269

Mitre link : CVE-2026-82269

CVE.ORG link : CVE-2026-82269


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel